Privacy

What we collect, and what we never do with it.

The plain-English version of how Growth House handles your data: one AI vendor, no training on your data, no stored embeddings, named sub-processors, and deletion that actually deletes.

Effective June 4, 2026

Who we are

Growth House is the operating brand of Studio Sami LLC, a Florida limited liability company based in Davenport, Florida. This policy covers the Growth House marketing site and Studio OS, the platform that runs subscription builds. If you hired us for a one-time build that you host on your own infrastructure, your operational data lives with you, not us, and only the items in this policy that relate to our website and our business records apply.

What we collect

Account information you give us: name, email, business name, and the login details needed to access your portal. Client data you submit through your build: documents, prompts, answers, configurations, and the records your workflow processes. Outputs the workflow generates for you. Payment information, which is handled by Stripe; we never see or store full card numbers. Basic usage and security logs (such as sign-in events and errors) needed to operate the platform. We do not buy data about you, and we do not run advertising trackers on the portal.

How we use it

We use your information to build, run, and support your workflow, to authenticate you, to process payments, to send you service emails, and to keep the platform secure. We do not sell your data, we do not share it for advertising, and we do not use one client's data to do another client's work. Access to your data is limited to you and the operator running your build.

How AI processing works

Every AI step in your build runs on Anthropic's Claude models, accessed through Anthropic's commercial API, and only Anthropic. We do not send your data to OpenAI, Google, or any other AI provider for processing. Under Anthropic's commercial terms, the inputs and outputs we send are not used to train Anthropic's models, and Anthropic retains API traffic only briefly for abuse monitoring before discarding it. We do notbuild embeddings or a vector database from your documents, so there is no secondary AI copy of your data that outlives the original. You can review Anthropic's terms at anthropic.com/legal/commercial-terms.

Sub-processors

We rely on a small, named set of vendors to run the platform. Each is bound by its own terms and processes your data only to provide its service to us:
VendorWhat it doesWhere
SupabaseDatabase, file storage, and authenticationAmazon Web Services (United States)
Amazon Web ServicesUnderlying cloud infrastructure for the platformUnited States
AnthropicAI processing (Claude models) for the steps in your workflowUnited States
StripePayment processing for subscriptions and build feesUnited States
Google (Gmail API)Delivery of transactional and operator emailsUnited States
CloudflareDNS, content delivery, and network protectionGlobal edge network

Where your data is stored and how it is protected

Your data is stored in Supabase, on Amazon Web Services, encrypted at rest with AES-256 and in transit over TLS. Each client's data sits in its own scope: every table and every private storage bucket has Row Level Security enabled with policies tied to your organization, enforced at the database layer so a query can only return rows that belong to you. Operator accounts that can reach client data are protected by app-based two-factor authentication; client sign-in uses one-time email magic links, so there is no reusable client password to steal. Supabase is SOC 2 Type II certified and independently audited; you can verify that at supabase.com/security.

How long we keep it

We keep your data for as long as your account is active. Inside the platform, your documents, prompts, and outputs live in your scope until you delete them or cancel. At the AI layer, Anthropic retains API traffic only briefly for abuse monitoring and then discards it. We do not maintain a separate long-term archive of your prompts and outputs outside your own scope. After cancellation we provide a one-time export within 30 days, after which we delete your data from the live platform.

Deleting your data

You can ask us to delete a specific document, a set of responses, or your entire account, and we will remove it from the live database and from file storage, not just hide it. Because there are no embeddings or vector copies, there is no hidden second version to chase down. Encrypted backups age out on their normal rotation rather than being individually edited; if you need a hard backup-purge commitment in writing, we can include that in a data processing addendum. Email your request to the address at the bottom of this page.

Your rights

You can ask us what data we hold about you, ask us to correct it, export it, or delete it. If you are covered by a privacy law such as the GDPR or a US state privacy act, we honor the access, correction, deletion, and portability rights it gives you. For business-sensitive or regulated data, we can sign a data processing addendum that names our sub-processors and commits us in writing to the no-training, deletion, and breach-notification terms described here.

Security incidents

If we ever discover a breach that affects your data, we will notify you without undue delay, tell you what we know, and tell you what we are doing about it. We will not sit on it.

Changes to this policy

If we change this policy in a way that materially affects how we handle your data, we will update the date above and let active clients know. Continued use of the platform after a change means you accept the updated policy.

Contact

Questions about this policy, or a request about your data, go to sami@thestudiosami.com. We read every one.

Ready to stop being the bottleneck?

Book a 30-minute Build Consultation and we'll figure out what to build together. No pitch, no follow-up sequences. Or browse the templates and deploy something this week.